GLPI
cpe:2.3:a:glpi-project:glpi:*:*:*:*:*:*:*
- >= 9.5.0
A stored cross-site scripting vulnerability has been identified in GLPI versions 9.5.0 through 10.0.18. This issue allows a technician to use a malicious payload that is executed later when the kanban is viewed. The vulnerability has been patched in version 10.0.19.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the kanban.
Users can upgrade to GLPI version 10.0.19 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.